Move in this order
- Change the password, the email account first, then anything sharing that password
- Sign out everywhere. Most services have "log out of all devices" in security settings, which kills the attacker's existing session
- Enable 2FA if it was not on
- Check the recovery settings, attackers add their own recovery email or phone so they can walk back in later. Most people miss this step
- Check email rules and forwarding. A hidden forwarding rule is how they keep reading your mail after you lock them out
- Tell the people affected, contacts, your bank, your provider
If money moved
Contact the provider immediately (minutes matter) and report to the police or the national cybercrime unit. Keep screenshots of everything; you will need them.
The mistake to avoid
Shame keeps people quiet, and the delay is what makes it worse. Sophisticated, well-resourced people fall for these too. Report early and loudly.
Afterwards
Change reused passwords everywhere, get a password manager, and treat it as the moment your habits improved.